← Back to feed
Vulnerabilities & PatchesEmerging1 sourceNov 24, 2021 · 18:31via API Security News

Issue 161: Vulnerability in Wipro Holmes Orchestrator, report into vulnerabilities in FinTech and banking apps

Brief

This week, we have details of a vulnerability in the AI platform Wipro Holmes Orchestrator, allowing the download of arbitrary files via path manipulation.

There’s also a new report from researcher Alissa Knight on vulnerabilities in banking, cryptocurrency exchange, and FinTech APIs; an article on the impact of a shift-left approach for API security; and 31 tips for improving API security; and an upcoming webinar on automating API protection.

Vulnerability: Arbitrary file download in Wipro Holmes Orchestrator

This week saw the disclosure of a vulnerability hat affected the AI platform Wipro Holmes Orchestrator, as detailed in this disclosure and tracked as CVE-2021-38146 .

The vulnerability was discovered by researcher Rizal Muhammed, who provided a sample Python script to demonstrate the exploit.

Read more on API Security News